Tier 3 SOC Analyst

Washington, DC, US • Posted 19 hours ago • Updated 19 hours ago
Full Time
No Travel Required
On-site
$120,000 - 127000/yr
Company Branding Image
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Access Control
  • Analytical Skill
  • Cyber Security
  • Endpoint Protection
  • Information Security
  • Intrusion Detection
  • IT Infrastructure
  • Incident Management
  • Malware Analysis
  • Tier 3
  • Threat Analysis
  • Vulnerability Scanning
  • SIEM
  • Perl
  • Scripting

Summary

Summary

The Tier 3 SOC Analyst is a cybersecurity technical resource who provides technical analytical oversight to a team of SOC analysts. The role monitors, detects, analyzes, remediates, and reports on cybersecurity events and incidents affecting the client's technology infrastructure, and serves as an advanced escalation point.

The ideal candidate has an advanced technical background and significant experience leading a SOC team or unit in an enterprise, responsible for analysis and correlation of cybersecurity event, log, and alert data. The candidate is skilled in recognizing and finding the root cause of exploits, vulnerabilities, and intrusions in host- and network-based systems.

Responsibilities

  • Use advanced technical and incident response experience to scrutinize and provide corrective analysis on cybersecurity events escalated from Tier 2 analysts, distinguish them from benign activity, and escalate confirmed incidents to the Incident Response Lead.
  • Provide in-depth analysis and trending/correlation of large data sets (logs, event data, alerts) from diverse network devices and applications to identify and troubleshoot specific incidents, and make sound technical recommendations for expeditious remediation.
  • Proactively search log, network, and system data to find undetected threats.
  • Support security tool and application tuning with analysts and engineers to develop and adjust rules, develop related response procedures, and reduce false-positive alerts.
  • Identify, verify, and ingest indicators of compromise and attack (IOCs, IOAs), such as malicious IPs and URLs, into network security tools to protect the network.
  • Quality-proof technical advisories and assessments before release from the SOC.
  • Coordinate with and provide expert technical support to enterprise-wide technicians and staff to resolve confirmed incidents.
  • Report common and repeat problems observed through trend analysis to SOC management, and propose process and technical improvements to alert notification and incident handling.
  • Formulate and coordinate technical best-practice SOPs and runbooks for SOC analysts.
  • Respond to inbound requests by phone and other electronic means for technical assistance and resolve problems independently. Coordinate escalations with the Incident Response Lead and collaborate with internal technology teams for timely resolution.

Minimum Qualifications

  • Bachelor's degree in Cyber Security or a related area with a minimum of five years of demonstrated operational experience as a cybersecurity analyst/engineer handling and coordinating incidents and response in critical environments, and/or equivalent knowledge in areas such as technical incident handling and analysis, intrusion detection, log analysis, penetration testing, and vulnerability management.
  • In-depth understanding of current cybersecurity threats, attacks, and countermeasures for adversarial activity such as network probing and scanning, DDoS, phishing, ransomware, botnets, and command and control (C2) activity.
  • In-depth hands-on experience analyzing and responding to security events and incidents with most of the following technologies and techniques: leading SIEM technologies, IDS/IPS, network- and host-based firewalls, network access control (NAC), data leak protection (DLP), database activity monitoring (DAM), web and email content filtering, vulnerability scanning tools, endpoint protection, and secure coding.
  • Strong knowledge of TCP/IP protocols, services, and networking.
  • Knowledge of forensic analysis techniques for common operating systems.
  • Adept at proactive search, solicitation, and detailed analysis of threat intelligence (exploits, IOCs, hacking tools, vulnerabilities, threat actor TTPs) from open-source resources and external entities, to identify threats and derive countermeasures not yet ingested into network security tools.
  • Excellent ability to multitask, prioritize, and manage time and tasks effectively.
  • Ability to work effectively in stressful situations.
  • Strong attention to detail.
  • Strong communication, interpersonal, organizational, oral, and customer service skills.

Required Experience

  • 5 years of hands-on operational experience as a cybersecurity analyst/engineer in a security operations center, or equivalent knowledge
  • 5 years of in-depth understanding of cybersecurity attack countermeasures for adversarial activity such as malicious code, DDoS, and phishing
  • 5 years of in-depth hands-on experience analyzing and responding to security events and incidents with a SIEM
  • 5 years of strong knowledge of cybersecurity attack methodology, including tactics, techniques, and associated countermeasures
  • 5 years of strong knowledge of TCP/IP protocols, services, and networking, and experience identifying, analyzing, containing, and eradicating cybersecurity threats
  • 11 years implementing, administering, and operating information security technology such as firewalls, IDS/IPS, SIEM, antivirus, network traffic analyzers, and malware analysis
  • 11 years of advanced experience with scripting and tool automation such as Perl, PowerShell, and Regex
  • 11 years developing, leading, and executing information security incident response plans
  • 11 years developing standard and complex IT solutions and services driven by business requirements and industry standards

Preferred Education/Certifications

  • Undergraduate degree in computer science, information technology, or a related field (BS in IT, Cybersecurity, Engineering, or equivalent experience highly desired)
  • SANS GCIA, GCED, GPEN, GCIH, or similar industry certification
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 90993969
  • Position Id: 9104020
  • Posted 19 hours ago

Company Info

About ICT Mondial Inc

ICT Mondial distinguishes itself as a premier technology consultancy dedicated to superior engineering and service delivery for clients across the public and private sectors. With over two and a half decades of industry experience, ICT Mondial delivers comprehensive Information and Communication Technology (ICT) solutions. It has a strong record in public sector tech initiatives, technology management consulting, and engineering excellence.

At the helm of organizational transformations, start-ups, and expansive growth, ICT Mondial has expertly managed substantial budgets exceeding $250 million and IT Client Teams exceeding 550 professionals. The firm prides itself on its project-based or hourly billing arrangements, tailored meticulously to each client's unique requirements. 

About_Company_OneAbout_Company_Two
Contact the job poster
BH

Beth Harris

Recruiter @ ICT Mondial Inc
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

It looks like there aren't any Similar Jobs for this job yet.

Search all similar jobs